<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Gumblar .cn Exploit &#8211; 12 Facts About This Injected Script</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: FK</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-11139</link>
		<dc:creator>FK</dc:creator>
		<pubDate>Wed, 29 Dec 2010 02:53:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-11139</guid>
		<description>Just to add some info.

Our clients sites, got inject, more than 200 sites, we have recovered all the sites, and seems to only have affect the index files, or at least the files that have common names.

We are still checking the wp sites but these seem more affected.

Still haven´t found the computer that originated the FTP &quot;hole&quot;, as many of the sites are not on more recent ftp softwares. But lesson learn don´t store passwords on the softwares.</description>
		<content:encoded><![CDATA[<p>Just to add some info.</p>
<p>Our clients sites, got inject, more than 200 sites, we have recovered all the sites, and seems to only have affect the index files, or at least the files that have common names.</p>
<p>We are still checking the wp sites but these seem more affected.</p>
<p>Still haven´t found the computer that originated the FTP &#8220;hole&#8221;, as many of the sites are not on more recent ftp softwares. But lesson learn don´t store passwords on the softwares.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Virus Removal</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-7560</link>
		<dc:creator>Virus Removal</dc:creator>
		<pubDate>Tue, 25 May 2010 08:51:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-7560</guid>
		<description>Hey, hopefully someone can make use of this 

If you are having issues running virus scanners whilst your computer is turned on, try to start into &#039;Safe Mode&#039;. 

If you&#039;re using a version of Windows, you&#039;ll be able to do this. (Windows XP, Windows Vista &amp; Windows 7)

Safe Mode:
Turn computer off
Turn computer on whilst tapping F8. When prompted select &#039;safe mode with networking&#039;
When prompted, click Yes &amp; start into Windows as normal.</description>
		<content:encoded><![CDATA[<p>Hey, hopefully someone can make use of this </p>
<p>If you are having issues running virus scanners whilst your computer is turned on, try to start into &#8216;Safe Mode&#8217;. </p>
<p>If you&#8217;re using a version of Windows, you&#8217;ll be able to do this. (Windows XP, Windows Vista &amp; Windows 7)</p>
<p>Safe Mode:<br />
Turn computer off<br />
Turn computer on whilst tapping F8. When prompted select &#8217;safe mode with networking&#8217;<br />
When prompted, click Yes &amp; start into Windows as normal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MMO-Champion got hacked - WoW-Raiders</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-7522</link>
		<dc:creator>MMO-Champion got hacked - WoW-Raiders</dc:creator>
		<pubDate>Sat, 22 May 2010 10:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-7522</guid>
		<description>[...] details For more details about Gumblar, see this Wikipedia article or this Unmask Parasites article. For a technical summary of Gumblar, there&#8217;s a nice article on iss.net about it. [...]</description>
		<content:encoded><![CDATA[<p>[...] details For more details about Gumblar, see this Wikipedia article or this Unmask Parasites article. For a technical summary of Gumblar, there&#8217;s a nice article on iss.net about it. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6957</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Sun, 04 Apr 2010 14:27:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6957</guid>
		<description>Hi,

1. The linked article is not about Gumblar. It describes a different infection (&lt;a href=&quot;http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/&quot; rel=&quot;nofollow&quot;&gt;this one&lt;/a&gt;)

2. Use the script at you own risk. The scripts used by this infection mutate every day and that removal script may not detect the new modifications (at best) or even corrupt your data (in worst case).

3. You don&#039;t need any removal scripts at all if you have a clean backup. Just remove everything and then restore the site from that backup.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>1. The linked article is not about Gumblar. It describes a different infection (<a href="http://blog.unmaskparasites.com/2009/12/23/from-hidden-iframes-to-obfuscated-scripts/" rel="nofollow">this one</a>)</p>
<p>2. Use the script at you own risk. The scripts used by this infection mutate every day and that removal script may not detect the new modifications (at best) or even corrupt your data (in worst case).</p>
<p>3. You don&#8217;t need any removal scripts at all if you have a clean backup. Just remove everything and then restore the site from that backup.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: digitalpbk</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6938</link>
		<dc:creator>digitalpbk</dc:creator>
		<pubDate>Wed, 31 Mar 2010 13:29:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6938</guid>
		<description>Hi i have made this script to remove all scripts on server using PERL. See the script @ &lt;a href=&quot;http://digitalpbk.com/virus/gumblar-web-virus-manual-removal-free-tool&quot; rel=&quot;nofollow&quot;&gt;Remove Gumblar Virus&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Hi i have made this script to remove all scripts on server using PERL. See the script @ <a href="http://digitalpbk.com/virus/gumblar-web-virus-manual-removal-free-tool" rel="nofollow">Remove Gumblar Virus</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Securing FTP Access on a cPanel Server :: The cPanel Admin</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6743</link>
		<dc:creator>Securing FTP Access on a cPanel Server :: The cPanel Admin</dc:creator>
		<pubDate>Thu, 11 Feb 2010 17:53:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6743</guid>
		<description>[...] with viruses like Gumblar stealing FTP passwords and farming them out to hackers so they can upload malicious code into user files. What you end up with is a flood of complaints from users about errors on their [...]</description>
		<content:encoded><![CDATA[<p>[...] with viruses like Gumblar stealing FTP passwords and farming them out to hackers so they can upload malicious code into user files. What you end up with is a flood of complaints from users about errors on their [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top 10 Malware Sites &#124; Decentralization Station &#124; Power of the cloud</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6514</link>
		<dc:creator>Top 10 Malware Sites &#124; Decentralization Station &#124; Power of the cloud</dc:creator>
		<pubDate>Wed, 06 Jan 2010 12:35:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6514</guid>
		<description>[...] malware researchers reported widespread compromises pointing to the domains gumblar.cn and martuz.cn, both of which made it on [...]</description>
		<content:encoded><![CDATA[<p>[...] malware researchers reported widespread compromises pointing to the domains gumblar.cn and martuz.cn, both of which made it on [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Malicious Javascript Code infected my blogs - Ryan Isra, Cyberworld, Technology</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6449</link>
		<dc:creator>Malicious Javascript Code infected my blogs - Ryan Isra, Cyberworld, Technology</dc:creator>
		<pubDate>Wed, 30 Dec 2009 19:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6449</guid>
		<description>[...] its name is Gumblar. You can find further information about Gumblar on Unmask Parasites Blog, Wikipedia, or ISS.net. I got alot of useful information. However, I might be infected by its [...]</description>
		<content:encoded><![CDATA[<p>[...] its name is Gumblar. You can find further information about Gumblar on Unmask Parasites Blog, Wikipedia, or ISS.net. I got alot of useful information. However, I might be infected by its [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Markusk</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6268</link>
		<dc:creator>Markusk</dc:creator>
		<pubDate>Wed, 16 Dec 2009 22:14:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6268</guid>
		<description>If you know the date of the infection, you can easily check all files that were edited on that day. 

btw, I noticed, it replaced a file called home.inc, so it probably also targets all files containing &quot;home&quot; in the name, additionally to &quot;index&quot;, &quot;default&quot;, etc and ALL .js files.</description>
		<content:encoded><![CDATA[<p>If you know the date of the infection, you can easily check all files that were edited on that day. </p>
<p>btw, I noticed, it replaced a file called home.inc, so it probably also targets all files containing &#8220;home&#8221; in the name, additionally to &#8220;index&#8221;, &#8220;default&#8221;, etc and ALL .js files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ugg outlet</title>
		<link>http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/comment-page-3/#comment-6214</link>
		<dc:creator>ugg outlet</dc:creator>
		<pubDate>Sun, 13 Dec 2009 12:49:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=181#comment-6214</guid>
		<description>Make sure to check the folders “error_docs” and “httpsdocs” on your webserver!!!

The malicious code can also be found in these locations – therefore the infection will not be cured if you just upload a clean backup version of your website from a clean system unless you sanitize those locations too.</description>
		<content:encoded><![CDATA[<p>Make sure to check the folders “error_docs” and “httpsdocs” on your webserver!!!</p>
<p>The malicious code can also be found in these locations – therefore the infection will not be cured if you just upload a clean backup version of your website from a clean system unless you sanitize those locations too.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

